U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2024-43776 - SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
    Published: September 02, 2024; 1:15:17 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2024-43775 - SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
    Published: September 02, 2024; 1:15:17 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2024-43774 - SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
    Published: September 02, 2024; 1:15:17 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2024-43773 - SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
    Published: September 02, 2024; 1:15:17 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2024-43772 - SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
    Published: September 02, 2024; 1:15:17 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2024-41160 - in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
    Published: September 02, 2024; 1:15:16 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2024-45270 - WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page ma... read CVE-2024-45270
    Published: September 01, 2024; 8:15:11 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2024-45269 - WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted pag... read CVE-2024-45269
    Published: September 01, 2024; 8:15:11 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2024-8366 - A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the component Update My Profile Page. The manipulation of t... read CVE-2024-8366
    Published: August 31, 2024; 2:15:13 PM -0400

    V3.1: 4.7 MEDIUM

  • CVE-2024-38354 - CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `name` attribute. This vulnerability enables attackers to perform cros... read CVE-2024-38354
    Published: July 10, 2024; 4:15:04 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2024-6750 - The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.3.14. This makes it possible for unaut... read CVE-2024-6750
    Published: July 23, 2024; 11:15:03 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2024-6751 - The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticate... read CVE-2024-6751
    Published: July 23, 2024; 11:15:03 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2024-6752 - The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient in... read CVE-2024-6752
    Published: July 23, 2024; 11:15:04 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2024-6753 - The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient i... read CVE-2024-6753
    Published: July 23, 2024; 11:15:04 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2024-6754 - The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14. This makes it possib... read CVE-2024-6754
    Published: July 23, 2024; 11:15:04 PM -0400

    V3.1: 4.3 MEDIUM

  • CVE-2024-6755 - The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. This ma... read CVE-2024-6755
    Published: July 23, 2024; 11:15:04 PM -0400

    V3.1: 5.3 MEDIUM

  • CVE-2024-6756 - The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authe... read CVE-2024-6756
    Published: July 23, 2024; 11:15:04 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2024-37559 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echenley Counterpoint allows Reflected XSS.This issue affects Counterpoint: from n/a through 1.8.1.
    Published: July 21, 2024; 3:15:05 AM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2024-37550 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Envato Template Kit – Export allows Stored XSS.This issue affects Template Kit – Export: from n/a through 1.0.22.
    Published: July 21, 2024; 3:15:04 AM -0400

    V3.1: 4.8 MEDIUM

  • CVE-2024-8344 - A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_area.php. The manipulation of the argument id leads to sql in... read CVE-2024-8344
    Published: August 30, 2024; 1:15:16 PM -0400

    V3.1: 8.8 HIGH

Created September 20, 2022 , Updated August 27, 2024